# Update by query problem

**URL:** <https://discuss.elastic.co/t/update-by-query-problem/137455>\
**Category:** Elasticsearch\
**Created:** [June 26, 2018, 2:55pm UTC](https://discuss.elastic.co/t/update-by-query-problem/137455 "2018-06-26T14:55:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jvolpi](https://avatars.discourse-cdn.com/v4/letter/j/96bed5/32.png) [@jvolpi](https://discuss.elastic.co/u/jvolpi)\
**Post date:** [June 26, 2018, 2:55pm UTC](https://discuss.elastic.co/t/update-by-query-problem/137455/1 "2018-06-26T14:55:18Z")

</div>

Hi everyone

I'm trying to create a new field in my index, and the value for it must be a substring from another field. This is my code:

```
POST logstash-2018.06.26/_update_by_query
{
    "script" : {
        "source": "ctx._source.seq = ctx._source.mensaje.substring(0, 2)",
        "lang": "painless"
    }
}

```

The new field would be 'seq'. The problem is that i'm getting null pointer exception in the substring function. There is no null value in that field, and it happens with other \_source fields too. In fact, if i remove the substring function, it works just fine.

I cannot use doc fields because the field i need is analyzed/keyword, so i cannot apply the substring function on it.

Here is the error:

```
{
  "error": {
    "root_cause": [
      {
        "type": "script_exception",
        "reason": "runtime error",
        "script_stack": [
          "ctx._source.seq = ctx._source.mensaje.substring(0, 2)",
          " ^---- HERE"
        ],
        "script": "ctx._source.seq = ctx._source.mensaje.substring(0, 2)",
        "lang": "painless"
      }
    ],
    "type": "script_exception",
    "reason": "runtime error",
    "script_stack": [
      "ctx._source.seq = ctx._source.mensaje.substring(0, 2)",
      " ^---- HERE"
    ],
    "script": "ctx._source.seq = ctx._source.mensaje.substring(0, 2)",
    "lang": "painless",
    "caused_by": {
      "type": "null_pointer_exception",
      "reason": null
    }
  },
  "status": 500
}

```

Isn't the substring function supposed to be  
applicable to the ctx.\_source fields the same way it is applicable to params.\_source.field in a scripted field?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![jvolpi](https://avatars.discourse-cdn.com/v4/letter/j/96bed5/32.png) [@jvolpi](https://discuss.elastic.co/u/jvolpi)\
**Post date:** [June 26, 2018, 4:47pm UTC](https://discuss.elastic.co/t/update-by-query-problem/137455/2 "2018-06-26T16:47:14Z")

</div>

I apologize, given the fact that i've been testing a lot of stuff, i activated the field\_data in the 'mensaje' field. The problem was that the substring function couldn't operate on a field with that activated.

Sorry again, this topic is resolved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2018, 4:47pm UTC](https://discuss.elastic.co/t/update-by-query-problem/137455/3 "2018-07-24T16:47:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
